Running in production

Publish, back up and monitor an instance that people depend on

  1. Before you go live
  2. Production checklist
  3. In this section

Before you go live

The defaults get an instance running quickly, but several of them are only meant for a first look. AnsibleForms logs a [SECURITY] warning at startup when ENCRYPTION_SECRET or ACCESS_TOKEN_SECRET is not set, and the Status page reports the backups, the retention settings and the expression sanitizer.


Production checklist

Go through these items once before users depend on the instance, and again after a major upgrade:

Item What to do Details
Admin password Change the password of the local admin account Hardening
Encryption secret Set ENCRYPTION_SECRET before you store any credential Secrets and encryption
Token secret Set ACCESS_TOKEN_SECRET, so sessions survive a restart Secrets and encryption
HTTPS Terminate TLS with your own certificate, not the sample one HTTPS
Reverse proxy Publish the instance behind a proxy, optionally under BASE_URL Reverse proxy
Schema endpoint Set ALLOW_SCHEMA_CREATION to 0 once the schema exists Hardening
Outbound calls Restrict REST expressions with REST_DENIED_HOSTS Hardening
Optional features Leave MCP and the chat assistant off unless you use them Hardening
Backups Check that the nightly backup works, and copy it off the host Backups
Retention Decide how long jobs and audit entries are kept Logs

In this section

Each topic has a page of its own; securing the instance is covered under Security:

Page What it covers
Reverse proxy Publish AnsibleForms behind Nginx, Traefik or Apache, at the root or under a subpath
Backups Nightly backups, what they contain, restores, and what else to keep
Logs Log files, syslog, the audit trail, and retention of jobs and audit entries